Last updated: 17 June 2026
Effective date: 17 June 2026
This Privacy Policy is published in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules framed thereunder, the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Who we are
StoreFlea ("StoreFlea", "we", "our", "us") operates a retail-business management platform that helps shopkeepers, retailers, distributors and food & dining businesses manage inventory, billing and invoicing, customers, online storefronts, QR-based dine-in ordering, and customer communications (including WhatsApp, SMS and email messaging for invoices, utility/transactional alerts and marketing).
This Policy applies to all StoreFlea products and surfaces, collectively the "Service", including:
• Shopkeeper Dashboard (web app)
• Shopkeeper Storefront Websites
• QR Dine-in / Smart Ordering web app
• StoreFlea Backend APIs and services
• Associated admin, notification, analytics and messaging services.
• AI Shop Assistant (natural-language questions about your own shop data)
• B2B Marketplace (shop-to-shop discovery, connections and ordering)
• Customer occasion greetings ("Wish Your Customer")
Contact: support@storeflea.com
2. Your role and our role under the DPDP Act
The DPDP Act uses the terms Data Principal (the individual the data is about) and Data Fiduciary (the entity that decides why and how the data is processed). A Data Processor processes data on behalf of a Data Fiduciary. StoreFlea acts in two distinct capacities:
2.1 When StoreFlea is the Data Fiduciary
For the personal data of our direct users — shopkeepers, business owners and their staff who register for and operate StoreFlea accounts — StoreFlea is the Data Fiduciary. We decide the purposes and means of processing this data (account creation, authentication, billing for our subscription, support, security).
2.2 When StoreFlea is the Data Processor
For the personal data of a shopkeeper's own customers (end-customers) that a shopkeeper enters into, uploads to, or generates through the Service — for example a customer's name, mobile number, billing address or purchase history — the shopkeeper is the Data Fiduciary and StoreFlea acts only as a Data Processor on the shopkeeper's behalf and under the shopkeeper's instructions.
Important — consent for end-customer data. The shopkeeper, as Data Fiduciary, is solely responsible for obtaining valid consent and providing the required notice to its own customers before collecting or processing their personal data through StoreFlea. This obligation is set out in our Terms and Conditions, which every shopkeeper accepts. StoreFlea processes such end-customer data only to provide the Service to the shopkeeper.
3. Personal data we collect
3.1 Shopkeeper / business-owner & staff data (StoreFlea as Fiduciary)
• Identity & contact: name, mobile number, email address.
• Credentials: password (stored only as a salted hash), OTPs, two-factor/2FA state, login session tokens, WhatsApp magic-link verification state.
• Business profile: business/shop name, business type, GSTIN, FSSAI number, business address and state, shop logo/branding (stored in object storage).
• Team data: names, mobile numbers, email and assigned roles (owner / admin / staff) of members you add.
• Subscription & payment data: subscription plan, billing status and payment references processed through our payment gateway. We do not store full card numbers.
• Support & communications: messages you send us and related correspondence.
3.2 End-customer data (StoreFlea as Processor for the shopkeeper)
• Identity & contact: customer name, one or more mobile numbers, email, GSTIN.
• Address: address, city, state, pincode.
• Commercial records: invoices, quotations, voucher/bill line items, products purchased, quantities, rates, taxes (CGST/SGST/IGST), payment type, ledger/party balances.
• CRM attributes: tags, segments, notes, preferred communication channel, and marketing opt-in status set by the shopkeeper.
• Analytics aggregates: total spend, visit count, first/last purchase date and similar derived metrics, used for the shopkeeper's business intelligence.
• Occasion dates: customer's date of birth and/or wedding anniversary, where the shopkeeper chooses to record them for greeting features.
3.3 Dine-in / QR ordering data
• Customer mobile number, table/session identifiers, items ordered, order status, payment method and uploaded payment receipts.
3.4 Storefront website data
• Information submitted by a visitor placing an order or enquiry on a shopkeeper's StoreFlea-hosted storefront (name, contact number, delivery details, cart/order contents).
3.5 Technical & usage data
• Device and connection data, IP address, user-agent/browser information, and timestamps.
• Security and audit logs, including an append-only deletion audit record (actor, IP, user-agent, reason) for account-deletion events.
• Cookies and similar technologies — see our Cookie Policy.
We do not knowingly collect special categories of sensitive data beyond what is described above.
3.6 B2B Marketplace data
When a shopkeeper enables the B2B Marketplace, we process: the shop's business profile shared for discovery (business name, type, location, catalogue of products marked as B2B), connection requests between shops, and B2B order records (line items, quantities, rates, taxes, order status) exchanged between a buyer shop and a supplier shop.
4. How and why we use personal data (purposes)
• Provide & operate the Service — account creation, billing, inventory, CRM, storefronts, QR ordering. Basis: performance of service / consent.
• Authentication & security — OTP, 2FA, session management, fraud and abuse prevention. Basis: legitimate use / consent.
• Transactional messaging — sending invoices/bills, order confirmations, payment receipts and utility alerts to customers via WhatsApp, SMS or email. Basis: processing on behalf of shopkeeper.
• Marketing messaging — shopkeeper-initiated marketing campaigns to opted-in customers. Basis: consent obtained by the shopkeeper.
• Analytics & business intelligence — sales, product and customer summaries for the shopkeeper. Basis: processing on behalf of shopkeeper.
• Subscription billing — charging shopkeepers for StoreFlea plans. Basis: performance of contract.
• Support & legal compliance — responding to queries, tax records, lawful requests. Basis: legal obligation / consent.
• AI Shop Assistant. Shopkeepers can ask free-text questions about their own shop's data. StoreFlea first computes the answer from the shopkeeper's own account data on our servers, then sends only the question and the already-computed figures to our AI provider to phrase a natural-language reply. These figures may include limited identifiers such as the names and mobile numbers of a shop's top customers or debtors, or the names of connected businesses, where relevant to the question. The AI provider never has access to StoreFlea's databases and receives no account identifiers. Basis: processing on behalf of the shopkeeper.
We process personal data only for the purposes for which it was collected (purpose limitation) and retain it only as long as necessary (storage limitation, see section 9).
5. Messaging & communications
StoreFlea sends messages to shopkeepers and, on a shopkeeper's behalf, to that shopkeeper's customers, over WhatsApp, SMS and email. These fall into the following categories:
• OTP / authentication — one-time passcodes and verification links.
• Invoice / bill — sending bill PDFs and invoice details.
• Utility / transactional — order updates, payment receipts, account and service notices.
• Marketing / campaigns — promotional messages sent only to recipients who have opted in.
Transactional and OTP messages are necessary to deliver the Service. Marketing messages are sent only where consent exists, and every marketing message provides a way to opt out. For end-customers, the shopkeeper is responsible for ensuring a valid consent and opt-out basis exists; StoreFlea provides suppression and opt-out tooling to support this.
Customer occasion greetings ("Wish Your Customer"). Where a shopkeeper enables this feature and has recorded a customer's birthday or anniversary, StoreFlea automatically sends a greeting message (and, if the shopkeeper configures one, an offer) to that customer via WhatsApp on the relevant date. These are marketing messages: they are sent on the shopkeeper's behalf and only where the shopkeeper has a valid consent and opt-out basis for that customer. Each such message provides a way to opt out.
6. Sharing & disclosure
We do not sell personal data. We share data only as needed to run the Service:
• Processors / sub-processors: cloud hosting and infrastructure (Amazon Web Services), messaging providers (WhatsApp/Meta, SMS gateways, email providers), and our payment gateway (Razorpay) for subscription billing. These parties process data under contract and only on our instructions.
• Between Fiduciary and Processor: a shopkeeper's end-customer data is accessible to that shopkeeper (the Fiduciary). StoreFlea staff access it only as a Processor for support, security and service operation.
• Legal & safety: where required by law, regulation, court order, or to protect rights, safety and prevent fraud.
• Business transfers: in connection with a merger, acquisition or reorganisation, subject to this Policy.
• AI provider: our AI features are powered by Anthropic's Claude models, accessed via Anthropic's API. The AI provider processes only the specific text sent for a request, solely to generate the response; it does not use this data to train its models and does not retain it beyond processing.
• Marketplace is shop-to-shop. When a shop connects with or places an order with another shop, that shop's own business-identity and order details become visible to the counterparty shop. Each shop is an independent Data Fiduciary for the data it receives about the other shop through the Marketplace and is responsible for its own lawful use of that data. StoreFlea transmits this data to operate the Marketplace on the shops' instructions.
7. Where your data is stored (data location)
All StoreFlea databases and services — including PostgreSQL, ClickHouse (analytics), caching, message queues and object storage — are hosted on public cloud in the India region (Asia Pacific – Mumbai).
Some messaging sub-processors (e.g. WhatsApp/Meta) may process limited data (such as a recipient phone number and message content) outside India in order to deliver messages. Any such transfer is limited to what is necessary to provide the messaging feature and is subject to applicable restrictions under the DPDP Act.
8. Security
We implement reasonable security safeguards, including: passwords stored as salted hashes, OTP/2FA, encrypted transport (HTTPS/TLS), access controls and tenant isolation per account, audit logging, and restricted internal access on a need-to-know basis. No system is completely secure; in the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.
When the AI Shop Assistant is served via Amazon Bedrock, processing stays in the India (Mumbai) region. When served via the Anthropic API, the request content may be processed outside India. Any such transfer is limited to what is necessary to generate the response and is subject to applicable restrictions under the DPDP Act.
9. Data retention & deletion
• We retain personal data for as long as your account is active and as needed to provide the Service.
• Certain records (e.g. tax invoices and financial records) may be retained for longer where required by Indian tax and accounting law.
• Account deletion follows a soft-delete + grace period + final purge lifecycle. When deletion is requested, data is marked for deletion, retained for a grace period during which the request can be cancelled, and then purged. An append-only deletion audit log is retained for compliance.
• When StoreFlea acts as Processor, end-customer data is deleted or returned on the shopkeeper's instruction or on termination of the shopkeeper's account, subject to legal retention requirements.
10. Your rights as a Data Principal
Under the DPDP Act you have the right to:
• Access a summary of your personal data and how it is processed.
• Correction, completion and updating of your personal data.
• Erasure of your personal data, subject to legal retention.
• Grievance redressal (see section 13).
• Nominate another individual to exercise your rights in case of death or incapacity.
• Withdraw consent at any time, as easily as it was given (withdrawal does not affect prior lawful processing).
How to exercise: Shopkeepers and staff can manage much of this in-app, or contact support@storeflea.com.
End-customers: if you are a customer of a shopkeeper and want to access, correct or delete your data, please contact the shopkeeper (the Data Fiduciary) directly. StoreFlea, as Processor, will assist that shopkeeper in fulfilling your request.
11. Consent & withdrawal
Where we rely on consent, we ask for it through clear notices and in-app prompts. You may withdraw consent at any time via in-app settings or by contacting us. Where StoreFlea acts as a Processor, the shopkeeper is responsible for obtaining and managing the consent of its own customers.
12. Children's data
The Service is intended for business users and is not directed at children. Consistent with the DPDP Act, we do not knowingly process the personal data of children (individuals under 18) without verifiable parental/guardian consent. Shopkeepers must not use the Service to process children's data without the consent required by law.
13. Grievance redressal
If you have any questions, concerns or complaints about how your personal data is handled, contact our Grievance Officer:
• Grievance Officer / Data Protection contact: support@storeflea.com
• Subject line: "DPDP / Privacy Grievance"
We will acknowledge and respond within the timelines prescribed by the DPDP Act. If unsatisfied, you may escalate to the Data Protection Board of India.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified in-app or by email. The "Last updated" date reflects the latest version.
Grievance Officer
Akshansh Gupta
Email: support@storeflea.com
Phone: 9755598800
381-382 Amrakunj colony Indore